Iranian-Linked Cyberattack Disrupts 30+ Minnesota Water Systems
A coordinated cyberattack targeted operational technology (OT) across more than 30 community water systems in Minnesota, disrupting pumps, wells, water towers, and wastewater lift stations. The incident, disclosed by Minnesota IT Services on July 28, 2026, forced several towns into manual operations but did not prompt any advisories for residents to alter water usage.
A leaked WaterISAC memo, marked TLP: AMBER, attributed the intrusions to Iranian-affiliated hackers, though no U.S. agency has formally confirmed the attribution. The memo, corroborated by The New York Times and The Washington Post, cited intelligence from federal officials and state fusion centers.
The attack exploited internet-facing programmable logic controllers (PLCs) from manufacturers like Rockwell Automation, Schneider Electric, and Siemens echoing a CISA advisory (AA26-097A) issued four days prior. The warning, which went largely unheeded, highlighted ongoing threats to U.S. water, energy, and government sectors, including confirmed disruptions and financial losses.
Key impacts included:
- Braham (pop. 1,700): Attackers disabled controls at the water treatment plant and well, forcing manual restoration within hours.
- Plymouth (pop. 80,000): Compromised cellular-linked equipment at water towers and lift stations was isolated to prevent further damage.
- Maple Plain and South St. Paul: Reported partial automation failures, though contingency plans maintained operations.
CISA later warned that attackers were changing PLC passwords to lock out operators, reiterating long-standing guidance to remove PLCs from public internet access and secure remote connections via VPNs.
The incident follows a November 2023 attack on Pennsylvania’s Municipal Water Authority of Aliquippa, where Iranian-linked actors defaced a Unitronics controller with an anti-Israel message exploiting default passwords. Despite repeated warnings, many small water systems lack dedicated cybersecurity resources.
The timing coincides with escalating tensions between the U.S. and Iran, including recent U.S. strikes near the Strait of Hormuz that disrupted water supplies for over 20,000 people. While the Minnesota disruptions were brief, the attack underscores persistent vulnerabilities in critical infrastructure.
Schneider Electric cybersecurity rating report: https://www.rankiteo.com/company/schneider-electric
City of Maplewood cybersecurity rating report: https://www.rankiteo.com/company/maplewoodmn
Southern Minnesota Municipal Power Agency cybersecurity rating report: https://www.rankiteo.com/company/southern-minnesota-municipal-power-agency
Siemens cybersecurity rating report: https://www.rankiteo.com/company/siemens
Rockwell Automation cybersecurity rating report: https://www.rankiteo.com/company/rockwell-automation
"id": "SCHMAPSOUSIEROC1785680820",
"linkid": "schneider-electric, maplewoodmn, southern-minnesota-municipal-power-agency, siemens, rockwell-automation",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'customers_affected': '1,700',
'industry': 'Water utilities',
'location': 'Braham, Minnesota',
'name': 'Braham Water Treatment Plant',
'size': 'Small (pop. 1,700)',
'type': 'Water treatment plant'},
{'customers_affected': '80,000',
'industry': 'Water utilities',
'location': 'Plymouth, Minnesota',
'name': 'Plymouth Water Systems',
'size': 'Large (pop. 80,000)',
'type': 'Water towers and lift stations'},
{'industry': 'Water utilities',
'location': 'Maple Plain, Minnesota',
'name': 'Maple Plain Water Systems',
'type': 'Water utilities'},
{'industry': 'Water utilities',
'location': 'South St. Paul, Minnesota',
'name': 'South St. Paul Water Systems',
'type': 'Water utilities'}],
'attack_vector': 'Exploitation of internet-facing programmable logic '
'controllers (PLCs)',
'customer_advisories': 'No advisories for residents to alter water usage',
'date_detected': '2026-07-28',
'date_publicly_disclosed': '2026-07-28',
'description': 'A coordinated cyberattack targeted operational technology '
'(OT) across more than 30 community water systems in '
'Minnesota, disrupting pumps, wells, water towers, and '
'wastewater lift stations. The incident forced several towns '
'into manual operations but did not prompt any advisories for '
'residents to alter water usage. The attack exploited '
'internet-facing programmable logic controllers (PLCs) from '
'manufacturers like Rockwell Automation, Schneider Electric, '
'and Siemens.',
'impact': {'operational_impact': 'Forced manual operations in multiple towns',
'systems_affected': ['Pumps',
'Wells',
'Water towers',
'Wastewater lift stations']},
'initial_access_broker': {'entry_point': 'Internet-facing PLCs'},
'lessons_learned': 'Persistent vulnerabilities in critical infrastructure due '
'to unsecured PLCs and lack of dedicated cybersecurity '
'resources in small water systems.',
'motivation': 'Disruption of critical infrastructure, geopolitical tensions',
'post_incident_analysis': {'root_causes': ['Unsecured internet-facing PLCs',
'Default passwords',
'Lack of network segmentation',
'Insufficient cybersecurity '
'resources']},
'recommendations': ['Remove PLCs from public internet access',
'Secure remote connections via VPNs',
'Change default passwords',
'Enhance monitoring of OT systems'],
'references': [{'source': 'WaterISAC memo (TLP: AMBER)'},
{'source': 'The New York Times'},
{'source': 'The Washington Post'},
{'source': 'CISA Advisory AA26-097A'}],
'response': {'containment_measures': ['Isolation of compromised equipment',
'Manual restoration of operations']},
'threat_actor': 'Iranian-affiliated hackers',
'title': 'Iranian-Linked Cyberattack Disrupts 30+ Minnesota Water Systems',
'type': 'Cyberattack on Operational Technology (OT)',
'vulnerability_exploited': ['Unsecured remote connections',
'Default passwords',
'Internet-exposed PLCs']}